- Salary
- $85 – $90
- Location
- FL-CLIENT-STATE, United States of America
- Workplace
- Remote
- Type
- Full-time
- Department
- Engineering
- Seniority
- Lead
- Education
- Certification
- Source
- Workday
Description
Req number:
R8266Employment type:
Full timeWorksite flexibility:
RemoteWho we are
CAI is a global services firm with over 9,000 associates worldwide and a yearly revenue of $1.3 billion+. We have over 40 years of excellence in uniting talent and technology to power the possible for our clients, colleagues, and communities. As a privately held company, we have the freedom and focus to do what is right—whatever it takes. Our tailor-made solutions create lasting results across the public and commercial sectors, and we are trailblazers in bringing neurodiversity to the enterprise.
Job Summary
We are looking for a motivated Lead AI/Agentic Identity Engineer ready to take us to the next level! If you have deep expertise in identity architecture, AI agent security, OAuth/OIDC, workload identity, and Zero Trust principles, and are looking for your next career move, apply now.Job Description
We are looking for a Lead AI/Agentic Identity Engineer to lead the design and implementation of an enterprise identity architecture for AI agents, autonomous workflows, and other non-human identities. The Lead AI/Agentic Identity Engineer will establish enterprise standards, governance models, and implementation blueprints that enable AI agents to operate as secure, auditable, and governed digital identities across cloud, hybrid, internal, and guest-facing environments. This position will be a contract and remote with occasional travel to Miami, FL.
Due to the specific legal and contractual requirements associated with this position, this role will be direct employment with CAI. This position does not offer work authorization sponsorship now or in the future.
What You'll Do
Define the enterprise target-state architecture for AI agent identity, authorization, governance, and auditability
Design operational models for governed non-human identities, including ownership, lifecycle management, registration, approval, attestation, recertification, and retirement
Create reusable reference architectures for agent onboarding, delegated access, tool invocation, runtime policy enforcement, and attribution
Lead architecture design across identity providers, CI/CD pipelines, agent platforms, secrets management systems, API gateways, service meshes, and cloud-native workload identity services
Develop implementation blueprints for cryptographic workload identity, including SPIFFE/SPIRE, mTLS, certificate-based authentication, short-lived credentials, and key lifecycle management
Define authorization frameworks utilizing OAuth 2.0/2.1, OIDC, token exchange, delegated authority models, audience-bound tokens, and just-in-time access controls
Establish architecture standards for Model Context Protocol (MCP), Agent2Agent (A2A), multi-agent orchestration, and secure tool-calling systems
Design policy decision and enforcement models across APIs, services, workloads, and AI runtimes
Guide implementation of runtime guardrails, including human-in-the-loop approvals, step-up authentication, revocation controls, rate limiting, transaction thresholds, and emergency stop capabilities
Partner with security, infrastructure, platform, and application teams to align AI identity controls with Zero Trust, privileged access management, secrets management, vulnerability management, and detection engineering programs
Define telemetry, logging, audit, and traceability requirements across user, agent, sub-agent, tool, and data access interactions
Lead architecture reviews, threat modeling exercises, design workshops, and implementation planning sessions
Develop executive-facing roadmaps, architecture decision records, implementation guidance, control mappings, and knowledge transfer materials
What You'll Need
Required:
10+ years of experience in enterprise security architecture, IAM architecture, cloud security, platform security, or application security
Proven experience designing and implementing enterprise IAM, workload identity, or non-human identity solutions at scale
Deep expertise in identity providers, OAuth/OIDC, service-to-service authentication, token security, API security, and cloud authorization frameworks
Strong knowledge of Zero Trust architecture, least privilege principles, privileged access management, identity governance, access certification, and policy-based access control
Experience designing secure architectures for distributed systems, APIs, microservices, containers, service meshes, and hybrid or multi-cloud environments
Ability to design deterministic security controls for autonomous and AI-enabled systems
Familiarity with agentic AI security concepts, AI agent runtimes, delegated authority, tool-calling frameworks, and AI-specific risks such as prompt injection, excessive agency, unsafe tool usage, and autonomous process escalation
Experience leading cross-functional architecture workshops and translating business, security, risk, and compliance requirements into technical solutions
Strong written and verbal communication skills with experience producing architecture documentation, design standards, implementation guides, executive summaries, and governance artifacts
Preferred:
Experience with AI agent frameworks, orchestration platforms, MCP, A2A, or emerging agent identity standards
Experience with SPIFFE/SPIRE, workload identity federation, service mesh security, mTLS, PKI, and certificate lifecycle management
Experience implementing policy-as-code solutions, runtime authorization frameworks, ABAC/ReBAC models, or centralized policy decision points
Experience designing security controls for highly regulated, privacy-sensitive, SOX, PCI, or high-availability environments
Experience developing security maturity models, capability roadmaps, governance frameworks, and executive investment strategies for emerging technologies
Physical Demands
Ability to safely and successfully perform the essential job functions consistent with the ADA and other federal, state, and local standards
Sedentary work that involves sitting or remaining stationary most of the time with occasional need to move around the office to attend meetings, etc.
Ability to conduct repetitive tasks on a computer, utilizing a mouse, keyboard, and monitor
Reasonable accommodation statement
If you require a reasonable accommodation in completing this application, interviewing, completing any pre-employment testing, or otherwise participating in the employment selection process, please direct your inquiries to [email protected] or (888) 824 – 8111.
EEO Statement
It is the policy of Computer Aid, Inc.(CAI) not to discriminate against any employee or applicant for employment because of race, color, religion, sex, sexual orientation, gender identity, national origin, age, marital status, genetic information, disability or because he or she is a protected veteran. It is also the policy of CAI to take affirmative action to employ and to advance in employment, all persons regardless of race, color, religion, sex, sexual orientation, gender identity, national origin, age, marital status, genetic information, disability or protected veteran status, and to base all employment decisions only on valid job requirements. This policy shall apply to all employment actions, including but not limited to recruitment, hiring, upgrading, promotion, transfer, demotion, layoff, recall, termination, rates of pay or other forms of compensation and selection for training, including apprenticeship, at all levels of employment.
Employees and applicants of CAI will not be subject to harassment on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, age, marital status, genetic information, disability or because he or she is a protected veteran. Additionally, retaliation, including intimidation, threats, or coercion, because an employee or applicant has objected to discrimination, engaged or may engage in filing a complaint, assisted in a review, investigation, or hearing or have otherwise sought to obtain their legal rights under any Federal, State, or local EEO law is prohibited.
$85-$90 per hourThe pay range for this position is listed above. Exact compensation may vary based on several factors, including location, experience, and education. Benefit packages include medical, dental, and vision insurance, as well as 401k retirement account access. Employees in this role may also be entitled to paid sick leave and/or other paid time off as provided by applicable law.